| CVE-2025-40947 | 7.5 | — | — | — | siemens / ruggedcom rox mx5000 firmware | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All | 151d ago |
| CVE-2025-40833 | 7.5 | — | — | — | — | The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requ | 151d ago |
| CVE-2026-2993 | 7.5 | — | — | — | — | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, | 151d ago |
| CVE-2026-7287 | 7.5 | — | — | — | zyxel / nwa1100-n firmware | ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), | 152d ago |
| CVE-2026-43873 | 7.5 | — | — | — | — | WWBN AVideo is an open source video platform. | 152d ago |
| CVE-2026-43668 | 7.5 | — | — | — | apple / ipados | A use after free issue was addressed with improved memory management. | 152d ago |
| CVE-2026-43661 | 7.5 | — | — | — | apple / ipados | A buffer overflow issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-43660 | 7.5 | — | — | — | apple / ipados | A validation issue was addressed with improved logic. | 152d ago |
| CVE-2026-43658 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-43654 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-43652 | 7.5 | — | — | — | apple / macos | A permissions issue was addressed with additional restrictions. | 152d ago |
| CVE-2026-39871 | 7.5 | — | — | — | apple / macos | A path handling issue was addressed with improved logic. | 152d ago |
| CVE-2026-39870 | 7.5 | — | — | — | apple / macos | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28991 | 7.5 | — | — | — | apple / ipados | An out-of-bounds read was addressed with improved bounds checking. | 152d ago |
| CVE-2026-28990 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28987 | 7.5 | — | — | — | apple / ipados | A logging issue was addressed with improved data redaction. | 152d ago |
| CVE-2026-28986 | 7.5 | — | — | — | apple / ipados | A race condition was addressed with additional validation. | 152d ago |
| CVE-2026-28983 | 7.5 | — | — | — | apple / ipados | A type confusion issue was addressed with improved checks. | 152d ago |
| CVE-2026-28976 | 7.5 | — | — | — | apple / macos | An information leakage was addressed with additional validation. | 152d ago |
| CVE-2026-28974 | 7.5 | — | — | — | apple / ipados | This issue was addressed with improved checks to prevent unauthorized actions. | 152d ago |
| CVE-2026-28969 | 7.5 | — | — | — | apple / ipados | A use after free issue was addressed with improved memory management. | 152d ago |
| CVE-2026-28965 | 7.5 | — | — | — | apple / ipados | A privacy issue was addressed with improved checks. | 152d ago |
| CVE-2026-28964 | 7.5 | — | — | — | apple / ipados | An inconsistent user interface issue was addressed with improved state management. | 152d ago |
| CVE-2026-28962 | 7.5 | — | — | — | apple / ipados | This issue was addressed with improved access restrictions. | 152d ago |
| CVE-2026-28959 | 7.5 | — | — | — | apple / ipados | A buffer overflow was addressed with improved bounds checking. | 152d ago |
| CVE-2026-28954 | 7.5 | — | — | — | apple / ipados | A file quarantine bypass was addressed with additional checks. | 152d ago |
| CVE-2026-28953 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28952 | 7.5 | — | — | — | apple / ipados | An integer overflow was addressed with improved input validation. | 152d ago |
| CVE-2026-28944 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28943 | 7.5 | — | — | — | apple / ipados | A logging issue was addressed with improved data redaction. | 152d ago |
| CVE-2026-28936 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved checks. | 152d ago |
| CVE-2026-28930 | 7.5 | — | — | — | apple / macos | A permissions issue was addressed with additional restrictions. | 152d ago |
| CVE-2026-28929 | 7.5 | — | — | — | apple / ipados | A logic issue was addressed with improved checks. | 152d ago |
| CVE-2026-28925 | 7.5 | — | — | — | apple / macos | A buffer overflow was addressed with improved bounds checking. | 152d ago |
| CVE-2026-28924 | 7.5 | — | — | — | apple / macos | A race condition was addressed with improved handling of symbolic links. | 152d ago |
| CVE-2026-28913 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28908 | 7.5 | — | — | — | apple / macos | A denial of service issue was addressed by removing the vulnerable code. | 152d ago |
| CVE-2026-28906 | 7.5 | — | — | — | apple / ipados | This issue was addressed through improved state management. | 152d ago |
| CVE-2026-28905 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28904 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28883 | 7.5 | — | — | — | apple / ipados | A use-after-free issue was addressed with improved memory management. | 152d ago |
| CVE-2026-28873 | 7.5 | — | — | — | apple / ipados | This issue was addressed with additional entitlement checks. | 152d ago |
| CVE-2026-28872 | 7.5 | — | — | — | apple / ipados | A resource exhaustion issue was addressed with improved input validation. | 152d ago |
| CVE-2026-28860 | 7.5 | — | — | — | apple / ipados | The issue was addressed with improved input validation. | 152d ago |
| CVE-2026-28848 | 7.5 | — | — | — | apple / macos | A buffer overflow was addressed with improved bounds checking. | 152d ago |
| CVE-2026-28846 | 7.5 | — | — | — | apple / ipados | A buffer overflow was addressed with improved bounds checking. | 152d ago |
| CVE-2026-2614exploited | 7.5 | 3.2% | 1/3 | +110d | lfprojects / mlflow | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3 | 152d ago |
| CVE-2026-7790 | 7.5 | — | — | — | ninenines / cowlib | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocatio | 152d ago |
| CVE-2026-7210 | 7.5 | — | — | — | python / python | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which | 152d ago |
| CVE-2026-4890 | 7.5 | — | — | — | — | A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a deni | 152d ago |
| CVE-2026-33361 | 7.5 | — | — | — | — | In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 2 | 152d ago |
| CVE-2026-33359 | 7.5 | — | — | — | — | In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), mo | 152d ago |
| CVE-2026-33357 | 7.5 | — | — | — | — | In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 22 | 152d ago |
| CVE-2026-31248 | 7.5 | — | — | — | — | Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. | 152d ago |
| CVE-2026-34092 | 7.5 | — | — | — | mediawiki / mediawiki | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. | 152d ago |
| CVE-2026-34091 | 7.5 | — | — | — | mediawiki / mediawiki | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. | 152d ago |
| CVE-2026-34090 | 7.5 | — | — | — | mediawiki / checkuser | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. | 152d ago |
| CVE-2026-34089 | 7.5 | — | — | — | wikimedia / scribunto | Vulnerability in Wikimedia Foundation Scribunto. | 152d ago |
| CVE-2026-34088 | 7.5 | — | — | — | mediawiki / mediawiki | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. | 152d ago |
| CVE-2026-34087 | 7.5 | — | — | — | mediawiki / mediawiki | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. | 152d ago |